Skip to content
Critical Vulnerability in Flatpak Allows Arbitrary File Write as Root

Critical Vulnerability in Flatpak Allows Arbitrary File Write as Root

First seen 23 Sep 2026, 19:54 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 23, 2026 at 20:58 UTC
  • CVE-2026-96275 allows arbitrary file write as root via compromised Flatpak repositories.
  • The vulnerability is due to improper symlink handling and path traversal in extract_extra_data.
  • Flatpak version 1.18.1 includes a patch; users should avoid untrusted sources.

A critical vulnerability (CVE-2026-96275) in Flatpak allows a malicious or compromised repository to write attacker-controlled content to arbitrary locations on the host filesystem, executing as root during system installs. The vulnerability arises from improper handling of symlinks and path traversal in the extract_extra_data function. Users must trust the repository to initiate an install or update, making the attack vector reliant on user action. Red Hat has issued a CVSS score of 7.5 (High) for this vulnerability, indicating significant risk. The issue has been patched in Flatpak version 1.18.1, and backports are available for LTS distributions. Users are advised to avoid installing Flatpak extensions from untrusted sources. The vulnerability was discovered by a researcher after a report from AISLE in collaboration with Red Hat.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-23
CVE-2026-96275 published
Red Hat disclosed a critical vulnerability in Flatpak that allows arbitrary file writes as root.
Red Hat
2026-09-23
Patch released for Flatpak
Flatpak version 1.18.1 was released to address the critical vulnerabilities identified.
GitHub
2026-09-23
Advisory issued
Users are advised to avoid installing Flatpak extensions from untrusted sources following the vulnerability disclosure.
GitHub

More articles in this cluster (2)